A vulnerability was found in NodeBB up to 4.14.x and classified as problematic. Affected by this issue is the function
renderEmoji of the component Emoji Rendering. Executing a manipulation of the argument tag.icon.url/tag.name can lead to cross site scripting.
The identification of this vulnerability is CVE-2026-73038. The attack may be launched remotely. There is no exploit available.
It is suggested to upgrade the affected component.